Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A web application for a IoT ingestion API is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?

⚠ Common exam trap

It's easy for candidates to confuse network-layer controls (like NACLs or security groups) with application-layer protection, assuming that blocking ports or IPs is sufficient to prevent SQL injection and XSS, when in fact these attacks require deep packet inspection of HTTP content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS WAF associated with the Application Load Balancer

AWS WAF is a web application firewall that integrates directly with an Application Load Balancer to filter and monitor HTTP/HTTPS requests. It provides managed rules specifically designed to block common attack patterns like SQL injection and cross-site scripting (XSS) with minimal operational overhead, as AWS manages the rule updates and scaling. This makes it the ideal choice for protecting the IoT ingestion API without requiring custom code or manual configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS WAF associated with the Application Load Balancer

    Why this is correct

    AWS WAF, when attached to an Application Load Balancer, acts as a web application firewall that inspects each HTTP(S) request at the application layer (Layer 7). It uses managed rule groups (e.g., AWS Managed Rules for SQL injection and XSS) and custom rules to filter and block malicious traffic before it reaches the backend instances. This is the appropriate service for detecting and mitigating SQL injection and cross-site scripting because it can parse HTTP headers, body, and URI patterns, and it integrates natively with ALB rules to allow, block, or count matching requests.

  • ✗

    Network ACLs on the public subnets

    Why it's wrong here

    Network ACLs are stateless, subnet-level filters that evaluate traffic based solely on IP addresses, ports, and protocols (Layer 3/4). They do not maintain connection state and cannot parse or inspect HTTP payload content, so they have no visibility into SQL injection or XSS payloads embedded in request bodies. Furthermore, because they are stateless, both inbound and outbound rules must be manually configured as a symmetric pair, but even with perfect rule configuration they remain blind to application-layer attack signatures.

  • ✗

    Security groups on the application instances

    Why it's wrong here

    Security groups act as virtual firewalls at the instance or ENI level, enforcing allow-list rules based on source/destination IP, port, and protocol (Layer 3/4). They are stateful, meaning return traffic is automatically permitted, but they evaluate traffic solely against these metadata criteria. Because they do not inspect the contents of HTTP requests, they cannot identify or block SQL injection attempts or XSS payloads, which are encoded within the application-layer data stream.

  • ✗

    AWS Shield Advanced only

    Why it's wrong here

    AWS Shield Advanced provides enhanced Distributed Denial of Service (DDoS) protection, including always-on network-layer and transport-layer monitoring, and mitigates volumetric attacks such as SYN floods and UDP reflection attacks. However, it does not perform application-layer inspection of HTTP request payloads for vulnerabilities like SQL injection or XSS; those require WAF rules. Shield Advanced may integrate with WAF to implement rate-based rules, but by itself it cannot detect or block web exploit patterns within traffic.

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.